Privacy Policy
Our approach in one paragraph
DealUnderwriter is built privacy-first. The deal inputs you enter (purchase prices, rents, expenses, addresses) stay in your browser unless you explicitly share a link or save a deal to an account. We collect the minimum personal information needed to run the Service, secure it, bill it, and improve it.
1. Information We Collect
a. Information you provide
- Account information. Email address and name when you create an account (via Clerk authentication).
- Billing information. If you subscribe, payment is processed by Stripe. We do not store full card numbers — only a customer ID and subscription metadata.
- Support messages. Content of emails or support requests you send us.
- AI chat messages. Prompts you send to our AI assistant are processed by our model provider (Anthropic via Vercel AI Gateway) and may be briefly logged for abuse prevention and debugging.
b. Information stored locally in your browser
Deal inputs, saved deals, notes, tags, and onboarding state are stored in your browser's localStorage. This data stays on your device unless you share a link or explicitly sync it to an account in a future release.
c. Automatically collected
- Usage analytics. We use Vercel Web Analytics and Speed Insights to understand which pages are visited, load times, and Core Web Vitals. This data is aggregated and does not identify individuals.
- Server logs. Our hosting provider (Vercel) logs standard request metadata (IP address, user agent, timestamps) for security and debugging. Logs are retained per Vercel's policy.
- Rate-limiting. We track API request counts per user or IP in memory for short windows to prevent abuse.
2. How We Use Information
- Provide, maintain, and improve the Service
- Authenticate users and secure accounts
- Process payments and manage subscriptions
- Respond to support requests
- Detect and prevent fraud or abuse
- Understand usage patterns to prioritize features
- Comply with legal obligations
We do not sell your personal information. We do not use your deal inputs or AI chats to train any machine learning model.
3. Service Providers
We share limited data with trusted providers strictly to run the Service:
- Vercel — hosting, analytics, edge functions
- Clerk — authentication & user management
- Stripe — payment processing
- Anthropic (via Vercel AI Gateway) — AI chat model
Each provider is contractually required to handle data in accordance with applicable privacy laws.
4. Cookies & Local Storage
We use cookies and localStorage for:
- Authentication session tokens (set by Clerk)
- Saved deals, notes, tags, and onboarding flags (in your browser only)
- Analytics cookies set by Vercel
You can clear browser storage at any time, which will remove saved deals and reset onboarding. Disabling cookies may prevent sign-in.
5. Data Retention
- Account data is retained while your account is active. If you delete your account, we remove personal identifiers within 30 days, subject to legal retention obligations.
- Browser-stored deals are retained in your browser until you delete them or clear storage.
- Billing records are retained as required by tax and accounting regulations (typically 7 years).
- Server logs follow our hosting provider's retention policy.
6. Your Rights
Depending on where you live (including California, the EU/UK, and certain other jurisdictions), you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your information
- Object to or restrict certain processing
- Data portability
- Withdraw consent where applicable
To exercise these rights, email privacy@dealunderwriter.ai. We will respond within the timeframe required by applicable law.
7. Security
We use industry-standard measures — HTTPS, encrypted storage at our providers, least-privilege access controls — to protect data. No system is perfectly secure; we cannot guarantee absolute security.
8. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will delete it.
9. International Users
The Service is operated from the United States. If you access it from outside the U.S., your information will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted here with an updated "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this policy or our data practices? Contact privacy@dealunderwriter.ai.